Security firm IntelCrawler says it has identified Target malware author
Security firm IntelCrawler said Friday that it has identified a Russian teenager as the author of the malware probably used in the cyberattacks against Target and Neiman Marcus, and that it expects more retailers to acknowledge that their systems were breached.
Context & Ripple Effects
The story lands mid-sequence: Target confirmed point-of-sale malware in its systems on January 12, Krebs on Security published a first technical look at that malware three days later, and on January 17 IntelCrawler disclosed it had found six ongoing attacks on U.S. merchants, with stolen Target card numbers flowing to a server in Russia.
What changes with this report is attribution: IntelCrawler says it has identified a Russian teenager as the likely author of the malware behind both the Target and Neiman Marcus intrusions, and it is publicly forecasting that more retailers have yet to admit breaches. The pickup was unusually wide — eight outlets including Forbes, The Verge, and SC Magazine ran the claim within a day.
First-order effects
- Retailers running compromised point-of-sale systems face immediate pressure to disclose: IntelCrawler itself expects more acknowledgments beyond Target and Neiman Marcus, whose own breach reached back to July before containment in mid-January.
- The named malware author gives investigators a concrete artifact to trace — if the code was sold rather than written per-victim, every merchant infected with the same strain can now be fingerprinted against one origin.
Second-order effects
- Commercial forensics firms like IntelCrawler turn attribution into a competitive product: naming an author generates coverage and positions the firm as the go-to investigator as new merchant victims surface from its list of six active attacks.
- Card issuers and payment processors absorb the downstream cost of the widening disclosure wave, as each newly acknowledged retailer adds millions of compromised numbers to reissue and fraud-monitoring queues.
Third-order effects
- If off-the-shelf POS malware keeps producing serial breaches across chains, checkout terminals stop being peripheral IT and become a board-level security category for retail — a shift already visible in the congressional inquiry prompted by the Target breach.
- Public attribution of malware authors by private firms establishes a pattern where breach investigations are narrated through security vendors' findings, shaping what regulators and Congress treat as the factual record.
The trend: Point-of-sale malware is commoditizing into reusable tools that hit retailer after retailer, while commercial forensics firms race to attribute the authors faster than the disclosure cycle unfolds.